Last updated on July 29, 2026
Version: 2.0
This Data Processing Agreement ("DPA") acts as a standard document for vendors or service providers who accept Infosys Supplier Code of Conduct or choose to sign a separate agreement. It applies to those wanting to provide services to Infosys Limited or its subsidiaries and affiliates across various regions (individually or collectively referred to as “Infosys”) whenever personal data processing activities are involved.
WHEREAS the Controller retains the Processor to deliver specified services (the "Services") in accordance with any agreement between the Parties, including but not limited to Purchase Orders or Statements of Work (“SOW”) (collectively referred to as the "Main Agreement").
WHEREAS, in providing the Services, the Processor may process Personal Data on behalf of the Controller.
WHEREAS the Parties wish to ensure that such processing complies with all Applicable Data Protection Laws (as defined in Section 1.9 and mapped in detail in Schedule A).
WHEREAS this DPA forms part of the Main Agreement and sets out the terms governing the processing of Personal Data.
NOW, THEREFORE, in consideration of the mutual promises and covenants contained herein, the Parties agree as follows:
1.1 "Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject"), however described under Applicable Data Protection Laws (including "personal data," "personal information," "digital personal data," or equivalent terms). This includes, without limitation, names, contact information, online identifiers, location data, and any categories of data that qualify as personal data or personal information under the relevant jurisdiction's laws. All such equivalent terms shall be treated as "Personal Data" for purposes of this DPA.
1.2 "Processing" means any operation or set of operations performed on Personal Data, whether by automated means, such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
1.3 "Controller" refers to the Infosys who determines the purposes and means of the Processing of Personal Data, however described under Applicable Data Protection Laws (including "data fiduciary," "business," "personal information handler," "personal information controller," or equivalent terms).
1.4 "Processor" refers to the vendor or service provider that processes Personal Data on behalf of Infosys, however described under Applicable Data Protection Laws (including "data processor," "service provider," "entrusted party," "personal information processor," "data intermediary," or equivalent terms).
1.5 "Subprocessor" means any third party engaged by the Processor to Process Personal Data on behalf of the Controller.
1.6 "Data Breach" means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
1.7 "AI Processing" means any use of artificial intelligence, machine learning, or automated decision-making systems in the Processing of Personal Data, including but not limited to training, inference, or model development.
1.8 "Sensitive Personal Data" means any category of Personal Data that is afforded heightened protection under Applicable Data Protection Laws, however described (including "special categories of data," "sensitive personal information," "sensitive personal data," or equivalent terms). This typically includes data relating to health, biometrics, religious or philosophical beliefs, financial accounts, racial or ethnic origin, sexual orientation, genetic data, and similar categories as defined under the relevant jurisdiction's laws.
1.9 "Applicable Data Protection Laws" or "Data Protection Laws" means, to the extent applicable to the Processing based on the location of Data Subjects, the Controller, or the Processing activities, any of the following (as mapped in Schedule A) and additional clauses referred under Schedule F: and any other data protection or privacy law applicable to the Personal Data processed under this Agreement.
1.10 Other terms such as "Data Subject Rights," "International Data Transfer," and "Supervisory Authority" shall have the meanings ascribed to them under the Applicable Data Protection Laws.
1.11 The Controller and Processor term used in this Agreement, shall be collectively referred to as the “Parties,” and each a “Party.”.
2.1 This DPA applies to all Processing of Personal Data by the Processor on behalf of the Controller in connection with the Services under the Main Agreement.
2.2 The nature, purpose, and duration of Processing, as well as the types of Personal Data and categories of Data Subjects, are described in Schedule A (attached hereto).
2.3 The Processor shall Process Personal Data only as necessary to provide the Services and in accordance with the Controller's documented instructions, unless required otherwise by applicable law (in which case, the Processor shall notify the Controller prior to such Processing, unless prohibited by law).
3.1 General Compliance
The Processor shall comply with all Applicable Data Protection Laws in Processing Personal Data. The Processor shall Process Personal Data only for the agreed purposes and shall not use Personal Data for its own purposes or sell, share, or use Personal Data for cross-context behavioral advertising or targeted advertising where prohibited (e.g., under CCPA/CPRA and US State Privacy Laws).
3.2 Confidentiality
The Processor shall ensure that all personnel authorized to Process Personal Data are bound by appropriate confidentiality obligations.
3.3 Security Measures
The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as detailed in Schedule B (Security Measures). Such measures shall include, as appropriate, pseudonymization, encryption, access controls, resilience measures, regular testing, incident response plans, and data classification, in accordance with the security obligations under all Applicable Data Protection Laws.
3.4 Subprocessing
The Processor may engage Subprocessor’s only with the Controller's prior written consent. The Processor shall impose equivalent data protection obligations on Subprocessor’s via contract and shall remain fully liable for their performance. A list of current Subprocessor’s is provided in Schedule C. The Processor shall not further sub-contract Processing to any other party without the Controller's consent and shall ensure all Subprocessor’s provide equivalent protection as required under Applicable Data Protection Laws.
3.5 Data Subject Rights
The Processor shall assist the Controller in fulfilling Data Subject requests, including requests for access, rectification, deletion, objection, portability, restriction, opt-out, withdrawal of consent, and explanation of automated decisions, within the timelines required by Applicable Data Protection Laws. The Processor shall cooperate promptly and provide all necessary information to enable the Controller to respond to such requests within the statutory deadlines of each relevant jurisdiction.
3.6 Data Protection Impact Assessments
The Processor shall assist the Controller with data protection impact assessments, privacy impact assessments, risk assessments, and prior consultations with supervisory authorities where required under Applicable Data Protection Laws.
3.7 Audits and Inspections
The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and shall allow for audits, including inspections, by the Controller or an auditor mandated by the Controller, at reasonable intervals and upon reasonable notice. The Processor shall also cooperate with relevant supervisory authorities as required under Applicable Data Protection Laws.
3.8 International Data Transfers
For international transfers of Personal Data, the Processor shall ensure appropriate safeguards are in place in compliance with Applicable Data Protection Laws. Such safeguards may include:
(a) Standard Contractual Clauses ("SCCs") under GDPR/LGPD, UK International Data Transfer Agreement ("IDTA"), or UK Addendum.
(b) Adequacy decisions issued by competent authorities.
(c) For transfers outbound from China under PIPL: CAC security assessments, CAC-approved standard contractual clauses, personal information protection certification, or applicable exemptions under the 2024 Provisions on Promoting and Regulating Cross-Border Data Flows (PIPL Article 38).
(d) For cross-border disclosures under the Privacy Act (Australia): reasonable steps under APP 8, including contractual clauses and due diligence, to ensure overseas recipients do not breach the APPs.
(e) For disclosures outside New Zealand under IPP 12: reasonable belief that the recipient provides comparable safeguards (e.g., via contractual obligations, OPC model clauses, equivalent laws, or informed individual consent).
(f) For PDPA (Singapore): ensuring comparable protection standards on overseas transfers.
(g) For Philippine DPA: adequate level of protection or binding contracts.
(h) For UAE PDPL/DIFC DPL: adequacy decisions, SCCs, or assessments.
(i) For other Applicable Data Protection Laws: such mechanisms as adequacy determinations, contractual safeguards, consent, or certification as required (e.g., Saudi PDPL, APPI Article 28, PIPA, Thailand PDPA, PIPEDA, Argentina PDPL, Peru PDPL, Chile DPL, Costa Rica DPL, Mauritius DPA).
The Processor shall not transfer Personal Data outside the relevant jurisdiction without the Controller's instructions and appropriate safeguards in place. Where Applicable Data Protection Laws require or recommend use of standard contractual clauses or transfer mechanism templates published by the relevant data protection authority, the Parties shall execute the applicable template(s) identified in Schedule D (Cross-Border Transfer Standard Clauses and Regulatory Templates), which shall form an integral part of this DPA.
3.9 Jurisdiction-Specific Obligations (Local Processing Agreements)
Where Schedule A indicates that one or more Applicable Data Protection Laws apply to the Processing, the jurisdiction-specific obligations set out in Schedule F (Local Processing Agreements) shall apply. Schedule F forms an integral part of this DPA, and the Processor shall comply with the obligations specified therein for each applicable jurisdiction.
4.1 AI Usage Restrictions. The Processor shall not use Personal Data for AI Processing, including training, fine-tuning, or improving AI models, without the Controller's explicit prior written consent. Any such consent must specify the purpose, scope, and safeguards.
4.2 Transparency in AI Processing. If AI Processing is authorized, the Processor shall provide detailed information on the AI systems used, including data inputs and outputs, algorithms, and decision-making processes, to enable the Controller to assess compliance with Applicable Data Protection Laws (e.g., automated decision-making under GDPR Article 22, LGPD Article 20, DPDP Act Section 12, PIPL Article 24, DIFC DPL automated decision-making provisions, APPI transparency requirements, and PIPA safeguards).
4.3 AI Compliance Obligations. The Processor shall ensure that any AI Processing complies with applicable AI-specific regulations, including but not limited to transparency, non-discrimination, and accountability requirements. The Processor warrants that AI systems do not introduce bias or violate Data Subject rights.
4.4 Data Minimization for AI. Personal Data used in AI Processing shall be minimized to what is necessary, anonymized or pseudonymized where possible, and not retained longer than required.
4.5 Prohibition on AI Data Retention for Third-Party Use. The Processor shall not retain, disclose, or use Personal Data in AI systems for its own or any third-party purposes, including model training beyond the authorized scope.
4.6 AI Incident Reporting. In addition to general Data Breach notifications under Section 5, the Processor shall promptly notify the Controller of any AI-related incidents, such as model errors leading to inaccurate Processing or unauthorized data exposure.
5.1 The Processor shall notify the Controller without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Data Breach, to enable the Controller to meet the shortest applicable notification deadline under any Applicable Data Protection Law.
5.2 Notifications shall include details of the breach, affected Personal Data, potential consequences, and remedial actions taken or proposed.
5.3 The Processor shall assist the Controller in notifying supervisory authorities and Data Subjects as required under Applicable Data Protection Laws.
6.1 The Controller warrants that it has all necessary rights, consents, and legal bases to provide Personal Data to the Processor and that the Processing instructions comply with Applicable Data Protection Laws.
6.2 The Controller shall provide the Processor with necessary information and cooperation to enable compliance with this DPA.
6.3 The Controller warrants compliance with all applicable controller or data fiduciary obligations under Applicable Data Protection Laws, including notice, consent, lawful basis, transparency, and impact assessment requirements as applicable in the relevant jurisdiction.
7.1 Upon termination of the Services or at the Controller's request, the Processor shall, at the Controller's choice, return or securely delete all Personal Data and copies thereof, unless retention is required by applicable law. Where Applicable Data Protection Laws require destruction, de-identification, or return upon completion of processing (including upon termination, expiration, or revocation of the engagement), the Processor shall comply with such requirements.
7.2 The Processor shall provide certification of deletion upon the Controller's request.
8.1 Each Party shall be liable for damages arising from its breach of this DPA, subject to any limitations set out in the Main Agreement.
8.2 The Processor shall indemnify the Controller against losses arising from the Processor's breach of Applicable Data Protection Laws or this DPA, including fines, claims, and remediation costs.
9.1 This DPA shall be governed by the laws of India, without regard to conflict of laws principles.
9.2 Disputes shall be resolved in accordance with the dispute resolution provisions in the Main Agreement.
10.1 This DPA may be amended only in writing signed by both Parties.
10.2 If any provision of this DPA is held to be invalid or unenforceable, the remainder of this DPA shall remain in full force and effect.
10.3 This DPA supersedes any prior agreements between the Parties regarding data processing.
IN WITNESS WHEREOF, the Parties have executed this DPA as of the Effective Date upon agreeing to the Infosys Supplier Code of Conduct.
The following table sets out the Data Protection Laws referenced in this DPA, their abbreviated terms, and the jurisdictions to which they apply. This mapping is used to determine which jurisdiction-specific obligations under Section 3.9 and Schedule F, and which cross-border transfer mechanisms under Section 3.8 and Schedule D, are applicable to the Processing.
| Jurisdiction | Legislation | Abbreviated Term |
|---|---|---|
| Argentina | Ley de Protección de los Datos Personales (Law No. 25,326) | Argentina PDPL |
| Australia | Privacy Act 1988 (Cth), including Australian Privacy Principles | Privacy Act / APPs |
| Brazil | Lei Geral de Proteção de Dados Pessoais (Law No. 13,709/2018) | LGPD |
| California, United States | California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 | CCPA/CPRA |
| Canada | Personal Information Protection and Electronic Documents Act, and applicable provincial privacy legislation | PIPEDA |
| Chile | Ley sobre Protección de la Vida Privada (Law No. 19,628) | Chile DPL |
| Costa Rica | Ley de Protección de la Persona frente al Tratamiento de sus Datos Personales (Law No. 8968) | Costa Rica DPL |
| Dubai International Financial Centre | Data Protection Law No. 5 of 2020 | DIFC DPL |
| EU/EEA | General Data Protection Regulation (EU) 2016/679 | GDPR |
| India | Digital Personal Data Protection Act, 2023, and Digital Personal Data Protection Rules, 2025 | DPDP Act and Rules |
| Japan | Act on the Protection of Personal Information | APPI |
| Malaysia | Personal Data Protection Act 2010 | Malaysia PDPA |
| Mauritius | Data Protection Act 2017 | Mauritius DPA |
| New Zealand | Privacy Act 2020, including Information Privacy Principles | NZ Privacy Act / IPPs |
| Oman | Personal Data Protection Law | Oman PDPL |
| People's Republic of China | Personal Information Protection Law | PIPL |
| Peru | Ley de Protección de Datos Personales (Law No. 29733) | Peru PDPL |
| Philippines | Data Privacy Act of 2012 (Republic Act No. 10173) | Philippine DPA |
| Puerto Rico | Applicable privacy laws of Puerto Rico | Puerto Rico Privacy Laws |
| Saudi Arabia | Personal Data Protection Law | Saudi PDPL |
| Singapore | Personal Data Protection Act 2012 | PDPA |
| South Africa | Protection of Personal Information Act | POPIA |
| South Korea | Personal Information Protection Act | PIPA |
| Thailand | Personal Data Protection Act B.E. 2562 | Thailand PDPA |
| United Arab Emirates | Personal Data Protection Law (Federal Decree-Law No. 45/2021) | UAE PDPL |
| United Kingdom | UK General Data Protection Regulation | UK GDPR |
| United States (various states) | Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, and other applicable U.S. state privacy laws | US State Privacy Laws |
Nature and Purpose of Processing: The Processor shall Process Personal Data on behalf of the Controller solely for the following purposes, as applicable to the Services under the Main Agreement:
- Provision of information technology services, including application development, maintenance, testing, infrastructure management, and cloud hosting.
- Business process management and outsourcing services, including transaction processing, data entry, and back-office operations.
- Consulting and advisory services, including management consulting, digital transformation, and strategy advisory.
- Engineering services, including product design, development, and lifecycle management.
- Human resources administration, including recruitment, onboarding, payroll processing, benefits administration, performance management, learning and development, and workforce management.
- Finance and accounting operations, including accounts payable and receivable, general ledger management, tax compliance support, and expense management.
- Customer relationship management, including sales support, client onboarding, customer service, and complaint handling.
- Procurement and supply chain management, including vendor management, purchase order processing, and logistics support.
- IT helpdesk, service desk, and end-user computing support.
- Data analytics, reporting, and business intelligence services.
- Cybersecurity and information security services, including security monitoring, threat detection, vulnerability management, and incident response.
- Communication and collaboration services, including email hosting, unified communications, and document management.
- Compliance, audit, and risk management support.
- Any other Processing activities specifically described in the Main Agreement or a Statement of Work.
Duration of Processing: Processing shall continue for the term of the Main Agreement (including any renewals or extensions) plus any applicable data retention periods required by Applicable Data Protection Laws or as specified in the Main Agreement.
Categories of Personal Data:
The following categories of Personal Data may be processed under this DPA, as applicable to the respective Services agreed:| Category | Description |
|---|---|
| Identity Data | Name, date of birth, age, gender, nationality, marital status, photograph, signature, government-issued identification numbers (e.g., national ID, passport, social security, tax identification numbers) |
| Contact Data | Residential and business addresses, personal and work email addresses, telephone and mobile numbers, emergency contact details |
| Professional and Employment Data | Job title, designation, department, employee ID, employer name, office location, work history, resume/CV, qualifications, certifications, professional memberships, start and end dates, employment type, manager details |
| Financial and Payroll Data | Bank account details, salary and compensation information, payroll records, tax withholding data, pension and provident fund details, expense reimbursement records, invoice and billing information |
| IT and Technical Data | IP addresses, device identifiers, MAC addresses, login credentials, system access and activity logs, cookies and tracking technologies, browser and operating system information, VPN and network access records |
| Communications Data | Business email content and metadata, chat and messaging logs, call recordings (where lawful), voicemail, support tickets, correspondence records |
| Usage and Behavioral Data | Service and application usage records, browsing and clickstream activity, preferences and settings, interaction and engagement data, training and learning records |
| Location Data | Office and work site location, business travel itineraries, geolocation data from devices (where applicable and lawful) |
| Recruitment and Candidate Data | Application form data, interview records and assessments, reference check information, background verification results (where lawful), offer and onboarding documentation |
| Benefits and Dependents Data | Insurance enrollment and claims data, dependents and beneficiary information (names, dates of birth, relationship), leave and attendance records, wellness program participation |
| Sensitive Personal Data | Health and medical data (including occupational health, disability accommodations, insurance claims), biometric data (fingerprints, facial recognition for access control), racial or ethnic origin, religious or philosophical beliefs, trade union membership, genetic data, sexual orientation, criminal background check results (only where specifically identified and required by law, with additional safeguards) |
Categories of Data Subjects: The following categories of Data Subjects may be affected by the Processing under this DPA, as applicable to the Services:
| Category | Description |
|---|---|
| Employees and Workers | Current and former employees, contractors, temporary staff, consultants, interns, secondees, and other workers of the Controller or its affiliates and group entities |
| Job Applicants and Candidates | Individuals who apply for employment, engagement, or internship with the Controller, including referred candidates |
| Clients and Customers | Individuals who are clients or customers of the Controller, or authorized representatives, employees, and contact persons of corporate clients |
| Business Contacts and Third Parties | Representatives, agents, officers, directors, and personnel of the Controller's suppliers, vendors, partners, advisors, auditors, regulators, and other business counterparties |
| End Users and Service Recipients | Individuals who use, access, or interact with the Controller's products, platforms, applications, or services |
| Website and Digital Property Visitors | Individuals who visit the Controller's websites, portals, mobile applications, or other digital properties |
| Dependents and Beneficiaries | Family members, dependents, nominees, or beneficiaries of employees or workers for insurance, benefits, pension, and emergency contact purposes |
| Trainees and Learners | Individuals enrolled in training, certification, or learning programs administered by or on behalf of the Controller |
Special Categories / Sensitive Personal Data: [Specify if applicable, with additional safeguards. Where Sensitive Personal Data is processed, the Parties shall ensure that explicit consent or another valid legal basis has been obtained in accordance with Applicable Data Protection Laws, and that enhanced technical and organizational measures are implemented as set out in Schedule B.]
The Processor shall implement and maintain the following baseline technical and organizational measures to protect Personal Data. These measures shall be proportionate to the nature, scope, context, and purposes of the Processing, and the risks to the rights of Data Subjects. The Processor shall regularly review and update these measures to ensure continued effectiveness and compliance with Applicable Data Protection Laws.
The Processor shall maintain an information security management system aligned with recognized standards (e.g., ISO/IEC 27001 or equivalent). The Processor shall designate a responsible individual or team accountable for information security and data protection. All personnel with access to Personal Data shall be subject to binding confidentiality obligations and shall receive regular training on data protection, information security, and awareness of Data Breach risks. The Processor shall maintain and enforce acceptable use policies, clear desk and clear screen policies, and role-based segregation of duties. The Processor will conduct background checks on personnel with access to Personal Data, to the extent permitted by applicable law.
The Processor shall implement physical access controls at all facilities where Personal Data is processed or stored, including perimeter security, access card systems, visitor management procedures, and CCTV surveillance. Data center facilities shall be protected by multi-layered physical security controls, including biometric access, mantrap entries, 24/7 security personnel, and environmental controls (fire suppression, climate control, flood detection, and uninterruptible power supply). Physical media containing Personal Data shall be securely stored and disposed of through certified destruction methods when no longer required.
The Processor shall implement role-based access controls (RBAC) ensuring that access to Personal Data is limited to authorized personnel on a need-to-know basis. Multi-factor authentication (MFA) shall be required for remote access, privileged accounts, and access to systems containing Sensitive Personal Data. The Processor shall enforce strong password policies, including complexity requirements, periodic rotation, and account lockout after failed authentication attempts. User access rights shall be reviewed periodically (at least quarterly for privileged accounts) and promptly revoked upon termination of employment or change of role. All access to systems containing Personal Data shall be logged and monitored.
The Processor shall implement network security controls including firewalls, intrusion detection and prevention systems (IDS/IPS), network segmentation, and secure configuration baselines for all infrastructure components. The Processor shall maintain patch management procedures to ensure timely application of security patches and updates to operating systems, applications, and firmware. The Processor shall deploy endpoint protection solutions (anti-malware, endpoint detection and response) on all devices that access or process Personal Data. Remote access shall be secured through encrypted VPN connections or equivalent secure access solutions.
The Processor shall implement encryption of Personal Data at rest using industry-standard algorithms (e.g., AES-256 or equivalent). All transmissions of Personal Data shall be encrypted in transit using TLS 1.2 or higher, or equivalent protocols. Encryption key management procedures shall be documented, including secure key generation, storage, rotation, and destruction. The Processor shall apply pseudonymization and anonymization techniques where appropriate to minimize the risk of identification of Data Subjects.
The Processor shall maintain a data classification framework that categorizes Personal Data based on sensitivity and applicable regulatory requirements. Handling procedures shall be defined for each classification level, addressing collection, storage, transmission, retention, and disposal. Sensitive Personal Data shall be subject to enhanced protection measures, including additional access restrictions, encryption requirements, and audit logging. The Processor shall maintain an inventory of systems and applications that process Personal Data.
The Processor shall follow secure software development lifecycle (SDLC) practices, including security requirements analysis, secure coding standards, code review, and security testing. The Processor shall conduct regular vulnerability assessments and penetration testing (at least annually, or upon material changes) of applications and infrastructure that process Personal Data. The Processor shall remediate identified vulnerabilities in accordance with documented timelines based on severity.
The Processor shall maintain a documented incident response plan covering identification, containment, investigation, eradication, recovery, and post-incident review of security incidents and Data Breaches. The Processor shall operate security monitoring capabilities (e.g., Security Information and Event Management (SIEM)) to detect and respond to potential security incidents in a timely manner. The Processor shall conduct incident response exercises and tabletop simulations at least annually. Incident response procedures shall be aligned with the breach notification timelines set out in Section 5 of this DPA.
The Processor shall maintain business continuity and disaster recovery plans to ensure the availability and resilience of systems processing Personal Data. The Processor shall perform regular backups of Personal Data and test restoration procedures at least annually. Business continuity plans shall include defined recovery time objectives (RTO) and recovery point objectives (RPO) appropriate to the nature of the Services. The Processor shall conduct business continuity exercises and update plans based on lessons learned.
The Processor shall conduct security due diligence assessments of all subprocessor’s prior to engagement and on a periodic basis thereafter. Subprocessor’s shall be contractually required to implement technical and organizational measures at least equivalent to those described in this Schedule B. The Processor shall maintain a risk-based monitoring program for subprocessor’s, including periodic reassessment of their security posture and compliance with contractual obligations.
The Processor shall retain Personal Data only for as long as necessary to fulfill the Processing purposes set out in Schedule A or as required by applicable law. Upon expiry of the retention period, termination of the engagement, or at the Controller's request, the Processor shall securely delete or destroy Personal Data using industry-standard methods (e.g., cryptographic erasure, degaussing, or physical destruction for media). The Processor shall provide certification of deletion upon the Controller's request.
The Processor shall maintain certifications or attestations demonstrating compliance with recognized security standards (e.g., ISO/IEC 27001, SOC 2 Type II, or equivalent). The Processor shall make audit reports, certifications, and relevant compliance documentation available to the Controller upon reasonable request. The Processor shall conduct internal audits of its security controls at least annually and shall remediate findings within documented timelines.
These measures shall be aligned with the requirements of all Applicable Data Protection Laws and shall be subject to periodic review and enhancement.
[List all current Subprocessor’s, including names, locations, and purposes of processing. Include the process for notifying the Controller of updates to this list.]
| Subprocessor Name | Location | Purpose of Processing | Date Added |
|---|---|---|---|
| [Name] | [Country] | [Description] | [Date] |
| [Name] | [Country] | [Description] | [Date] |
Where international transfers of Personal Data are required under this DPA, the Parties shall execute the applicable transfer mechanism template(s) published or approved by the relevant data protection authority, as identified in the table below. Executed copies of such templates shall be appended to this DPA and shall form an integral part of this Agreement.
| Jurisdiction | Applicable Law | Transfer Mechanism / Template | Issuing Authority |
|---|---|---|---|
| EU/EEA | GDPR | EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) - Module 2 (Controller-to-Processor) or Module 3 (Processor-to-Processor) or Module 4 (Processor to Controller) as applicable In case of vendors who are independent controllers, then Module 1 (Controller to Controller) will apply | European Commission |
| United Kingdom | UK GDPR | UK International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs | UK Information Commissioner's Office (ICO) |
| Brazil | LGPD | ANPD Standard Contractual Clauses (when published; interim: clauses substantially equivalent to EU SCCs adapted to LGPD) | Autoridade Nacional de Proteção de Dados (ANPD) |
| China | PIPL | CAC Standard Contract for Cross-Border Transfer of Personal Information (Measures effective June 2023) | Cyberspace Administration of China (CAC) |
| Australia | Privacy Act / APPs | APP 8 Contractual Clauses (OAIC recommended model clauses or equivalent contractual protections) | Office of the Australian Information Commissioner (OAIC) |
| New Zealand | NZ Privacy Act / IPPs | OPC Model Privacy Clauses for Cross-Border Disclosure | Office of the Privacy Commissioner (OPC) |
| Singapore | PDPA | PDPC Model Data Protection Clauses for Cross-Border Transfers | Personal Data Protection Commission (PDPC) |
| Philippines | Philippine DPA | NPC Model Contractual Clauses (where available; interim: contractual clauses ensuring adequate protection) | National Privacy Commission (NPC) |
| UAE | UAE PDPL | UAE Data Office Standard Contractual Clauses (when issued; interim: clauses substantially equivalent to EU SCCs adapted to UAE PDPL) | UAE Data Office |
| DIFC | DIFC DPL | DIFC Commissioner's Standard Contractual Clauses | DIFC Commissioner of Data Protection |
| Saudi Arabia | Saudi PDPL | SDAIA Standard Contractual Clauses or approved transfer mechanisms (when issued; interim: equivalent contractual protections) | Saudi Data and Artificial Intelligence Authority (SDAIA) |
| Japan | APPI | PPC Guidelines on Cross-Border Transfer – Consent or Equivalency Framework | Personal Information Protection Commission (PPC) |
| South Korea | PIPA | PIPC Standard Contractual Clauses (when published; interim: equivalent contractual protections) | Personal Information Protection Commission (PIPC) |
| Thailand | Thailand PDPA | PDPC Thailand Standard Contractual Clauses (when issued; interim: equivalent contractual protections) | Personal Data Protection Committee (PDPC Thailand) |
| South Africa | POPIA | Information Regulator Approved Transfer Mechanisms (when issued; interim: equivalent contractual protections) | Information Regulator |
| Malaysia | Malaysia PDPA | PDP Commissioner Transfer Guidance (when issued; interim: equivalent contractual protections) | Personal Data Protection Commissioner |
| Oman | Oman PDPL | MTCIT Approved Transfer Mechanisms (when issued; interim: equivalent contractual protections) | Ministry of Transport, Communications and Information Technology (MTCIT) |
| Canada | PIPEDA | Contractual clauses ensuring substantially similar protection (PIPEDA Schedule 1, Principle 4.1.3) | Office of the Privacy Commissioner of Canada (OPC) |
| Argentina | Argentina PDPL | AAIP-approved transfer clauses or adequacy-based transfer (Argentina holds EU adequacy status) | Agencia de Acceso a la Información Pública (AAIP) |
| Peru | Peru PDPL | ANPDP-approved contractual clauses (when issued; interim: equivalent contractual protections) | Autoridad Nacional de Protección de Datos Personales (ANPDP) |
| Chile | Chile DPL | Contractual clauses ensuring equivalent protection (when issued under reformed framework; interim: equivalent contractual protections) | Consejo para la Transparencia / Future Data Protection Authority |
| Costa Rica | Costa Rica DPL | PRODHAB-approved transfer mechanisms or equivalent contractual protections | Agencia de Protección de Datos de los Habitantes (PRODHAB) |
| Mauritius | Mauritius DPA | DPO-approved contractual clauses or equivalent safeguards | Data Protection Office (DPO) |
This template may be used to document assessments for international transfers of Personal Data, in alignment with the EDPB Recommendations 01/2020, the CJEU Schrems II judgment, and equivalent guidance from other authorities. A separate assessment should be completed for each transfer destination.
- Data Exporter: [Controller Name], [Jurisdiction], [Role: Controller/Processor]
- Data Importer: [Processor/Vendor Name], [Country], [Role: Processor]
- Contact Persons: [Names/emails]
- Categories of Data Subjects: [e.g., Customers, employees, website users]
- Types of Personal Data: [e.g., Name, email, IP address, billing information; sensitive data: Yes/No]
- Volume/Frequency: [e.g., Ongoing, approximately 10,000 records/month]
- Purpose: [e.g., Cloud hosting, analytics, customer support per Main Agreement]
- Transfer Tool Relied On: [e.g., 2021 EU SCCs (Module 2 Controller-to-Processor) + UK Addendum / DPF certification]
- Destination Country: [e.g., United States]
- Onward Transfers/Sub-processors: [Yes/No; list if applicable]
- Adequacy Decision: [Yes/No; if yes, specify]
- If No Adequacy: Transfer tool = [SCCs/IDTA]; valid and executed: [Yes/No]
- Derogations (e.g., GDPR Art. 49): [Not relied on / Relied on (specify)]
- Relevant Legislation: [e.g., For US: FISA 702, EO 12333, CLOUD Act]
- Government Access Risk: [Description of surveillance scope and likelihood]
- Practical Application: [Assessment of likelihood of access to the specific dataset]
- Importer Commitments: [e.g., No knowledge of incompatible requests; notifies exporter per SCC Clause 14]
- Overall Risk Level: [Low / Moderate / High]
- Supplementary Measures Required: [Yes / No]
| Category | Measure | Effectiveness Rationale |
|---|---|---|
| Technical | End-to-end encryption (client-side, exporter controls keys) | Prevents access in cleartext even if compelled |
| Technical | Strong encryption in transit/at rest (AES-256+) and pseudonymization/anonymization | Reduces value if accessed |
| Technical | Data minimization and tokenization for non-essential fields | Limits exposure |
| Contractual | Importer notifies exporter of government requests and challenges where possible | Enhances transparency and enforceability |
| Contractual | Audit and inspection rights; cooperation on complaints | Accountability |
| Organizational | Regular risk re-evaluation; employee training; access logs | Ongoing monitoring |
If no effective measures are possible: [Suspend transfer / Seek derogation / Localize data].
Note: The Processor is obligated to maintain the Transfer Impact Assessment either in the template provided in Schedule E or any approved template, and when requested, shall provide the information to demonstrate compliance with applicable cross border data transfer requirements, in alignment with supplemental measures in addition to the Schedule B.The following jurisdiction-specific obligations apply only where Schedule A (Part 3: Jurisdictional Applicability) indicates that the relevant Applicable Data Protection Law applies to the Processing under this DPA. Each section below constitutes a Local Processing Agreement for the identified jurisdiction and forms an integral part of this DPA.
- The Processor shall process Personal Data only on the Controller's documented instructions and for the specified purposes, in compliance with Argentina's PDPL (Law No. 25,326) and its implementing regulations.
- The Processor shall implement technical and organizational security measures appropriate to the nature of the Personal Data, as required under the PDPL and applicable regulations of the Agencia de Acceso a la Información Pública (AAIP).
- The Processor shall assist the Controller in fulfilling Data Subject rights, including rights to access, rectification, deletion (supresión), and confidentiality, within the statutory timelines.
- The Processor shall not transfer Personal Data to countries or international bodies that do not provide adequate levels of protection, unless a recognized exception applies (e.g., contractual clauses, explicit consent, or Argentina's EU adequacy status).
- The Processor shall notify the Controller without undue delay of any Data Breach and shall cooperate with the Controller in responding to inquiries from AAIP.
- The Processor shall retain Personal Data only for as long as necessary for the agreed purposes and shall securely delete or return data upon termination of the engagement.
- Where the Processor holds Personal Data (including as an outsourced service provider), it shall comply with the APPs as an APP Entity, including APP 6 (use or disclosure only for permitted primary or secondary purposes), APP 11 (reasonable steps to protect from misuse, interference, loss, or unauthorized access, modification, or disclosure), and APP 8 (cross-border disclosure).
- The Processor shall assist the Controller with access, correction, and complaints handling under APPs 12–13.
- The Processor shall comply with any applicable requirements arising from 2024–2026 amendments, including enhanced transparency for automated decision-making under new APP 1.7 (effective 2026).
- The Processor shall retain Personal Data only for as long as necessary for the agreed purposes and shall take reasonable steps to destroy or de-identify data when no longer needed under APP 11.2.
- The Processor shall cooperate with the OAIC in any investigation or inquiry and shall maintain adequate records of Processing activities.
- The Processor shall comply with LGPD principles of purpose limitation, adequacy, necessity, transparency, and data security in all Processing activities.
- The Processor shall assist with ANPD notifications, including breach reporting and regulatory inquiries.
- The Processor shall support the Controller in responding to Data Subject rights requests, including access, correction, anonymization, portability, and deletion, within the timelines prescribed by LGPD.
- The Processor shall maintain records of Processing activities and cooperate with the Controller in preparing data protection impact reports (relatório de impacto) when required by ANPD.
- The Processor shall implement technical and administrative security measures adequate to protect Personal Data from unauthorized access, accidental or unlawful destruction, loss, alteration, or disclosure as required under Article 46.
- The Processor shall ensure that any international transfer of Personal Data complies with LGPD Chapter V requirements, including use of SCCs or other approved mechanisms.
- The Processor shall process Personal Data only for the purposes identified by the Controller and in accordance with PIPEDA Principle 4.2 (Identifying Purposes) and Principle 4.5 (Limiting Use, Disclosure, and Retention).
- The Processor shall implement security safeguards appropriate to the sensitivity of the Personal Data, as required under PIPEDA Principle 4.7 (Safeguards), including physical, organizational, and technological measures.
- The Processor shall assist the Controller in responding to Data Subject (individual) access requests and challenges to accuracy under PIPEDA Principles 4.9 (Individual Access) and 4.6 (Accuracy).
- The Processor shall notify the Controller without undue delay of any Data Breach that creates a real risk of significant harm, to enable the Controller to report to the Office of the Privacy Commissioner of Canada and affected individuals as required under PIPEDA's breach notification provisions.
- The Processor shall not transfer Personal Data outside Canada without the Controller's instructions and shall ensure that any transfer is subject to contractual protections providing a comparable level of protection (PIPEDA Principle 4.1.3).
- The Processor shall comply with applicable provincial privacy legislation (e.g., Quebec Law 25, Alberta PIPA, British Columbia PIPA) where such legislation applies to the Processing, including enhanced consent, breach notification, and privacy impact assessment requirements.
- The Processor shall process Personal Data only on the Controller's documented instructions and in compliance with Chile's DPL (Law No. 19,628) and any applicable amendments or reformed data protection framework.
- The Processor shall implement appropriate security measures to protect Personal Data from unauthorized access, alteration, disclosure, or destruction.
- The Processor shall assist the Controller in fulfilling Data Subject rights, including rights to access, rectification, cancellation (deletion), and objection, as provided under the DPL.
- The Processor shall not transfer Personal Data outside Chile unless the recipient jurisdiction provides adequate protection or an exception applies (e.g., consent, contractual clauses, or legitimate interest under the applicable framework).
- The Processor shall notify the Controller without undue delay of any Data Breach and shall cooperate with the Controller in responding to inquiries from the relevant supervisory authority.
- The Processor shall retain Personal Data only for as long as necessary for the agreed purposes and shall securely delete or return data upon termination of the engagement.
- The Processor (as Entrusted Party) shall process Personal Data strictly within the scope agreed in this DPA (purpose, period, method, categories, and protection measures) and shall not process beyond such scope (PIPL Article 21).
- The Processor shall take necessary security measures and assist the Controller in responding to individual rights requests, breach notifications, and impact assessments (PIPL Article 59).
- Upon termination, expiration, invalidity, revocation, or completion of the entrustment, the Processor shall return or delete the Personal Data and shall not retain it (PIPL Article 21).
- The Processor shall allow and cooperate with supervision by the Controller of its processing activities (PIPL Article 21).
- The Processor shall not transfer Personal Data outside China without the Controller's instructions and appropriate safeguards, including execution or filing of CAC standard contracts if required, separate individual consent where mandated, and completion of an impact assessment.
- For transfers involving Sensitive Personal Data or large volumes, additional mechanisms (e.g., security assessment) may apply.
- The Processor shall process Personal Data only on the Controller's documented instructions and in compliance with Costa Rica's DPL (Law No. 8968) and its implementing regulations.
- The Processor shall implement appropriate technical and organizational security measures to protect Personal Data from unauthorized processing, loss, or damage.
- The Processor shall assist the Controller in fulfilling Data Subject rights, including rights to access, rectification, deletion, and restriction of Processing, as provided under the DPL.
- The Processor shall not transfer Personal Data outside Costa Rica without the Controller's instructions and shall ensure appropriate safeguards are in place, including contractual protections or PRODHAB-approved mechanisms.
- The Processor shall notify the Controller without undue delay of any Data Breach and shall cooperate with the Agencia de Protección de Datos de los Habitantes (PRODHAB) as required.
- The Processor shall retain Personal Data only for as long as necessary for the agreed Processing purposes and shall securely delete or return data upon termination of the engagement.
- The Processor shall Process Personal Data only on documented instructions from the Controller, in compliance with GDPR Articles 28 and 32 and the UK GDPR.
- The Processor shall assist with data protection impact assessments under Articles 35–36 and cooperate with supervisory authorities upon request.
- The Processor shall maintain a record of Processing activities carried out on behalf of the Controller as required under Article 30(2).
- Where Personal Data is transferred outside the EU/EEA or the UK, the Processor shall use SCCs, the UK IDTA, or other approved transfer mechanisms under Articles 46–49 and Schedule D.
- The Processor shall appoint a Data Protection Officer where required under Article 37.
- The Processor shall notify the Controller of any Data Breach without undue delay in accordance with Article 33.
- Upon termination or at the Controller's request, the Processor shall delete or return all Personal Data and certify such deletion, unless EU or Member State law requires continued storage.
- The Processor shall process Personal Data strictly per the Controller's instructions and only for the purposes specified in this DPA, in compliance with the Digital Personal Data Protection Act (DPDP Act’) and the Digital Personal Data Protection Rules, 2025 (Rules’).
- The Processor shall assist the Controller with consent management obligations, including facilitating withdrawal of consent by Data Subjects (Data Principals), and shall ensure that valid, informed, and specific consent is obtained and recorded as prescribed under the DPDP Act and Rules.
- The Processor shall support the Controller in fulfilling Data Subject (Data Principal) rights, including the right to access, correction, erasure, and nomination of a representative, within the timelines prescribed under the DPDP Act and Rules.
- Where the Controller is classified as a Significant Data Fiduciary, the Processor shall cooperate with additional compliance obligations under the DPDP Act and Rules, including periodic data audits by independent auditors, data protection impact assessments, appointment of a Data Protection Officer and an independent data auditor, and compliance with data localization requirements as may be notified by the Central Government.
- The Processor shall implement reasonable security safeguards as required under Section 8 of the DPDP Act and the corresponding provisions of the Rules, including encryption, access controls, and monitoring, to prevent Data Breaches. The Processor shall notify the Controller of any Data Breach without undue delay to enable the Controller to report to the Data Protection Board of India within the prescribed timelines.
- The Processor shall not retain Personal Data beyond the period necessary for the agreed Processing purpose and shall delete or return such data upon completion of Processing, termination of the engagement, or withdrawal of consent by the Data Principal, unless retention is required under applicable Indian law.
- The Processor shall comply with obligations regarding children's data, including obtaining verifiable consent from parents or lawful guardians where required, and shall not undertake tracking, behavioral monitoring, or targeted advertising directed at children.
- The Processor shall cooperate with any grievance redressal mechanisms established by the Controller under the DPDP Act and Rules and shall assist the Controller in responding to inquiries or directions from the Data Protection Board of India.
- The Processor shall securely handle Personal Data in accordance with the Controller's instructions and the requirements of the APPI.
- The Processor shall take necessary and appropriate measures to ensure the security of Personal Data, including preventing leakage, loss, or damage.
- For cross-border third-party transfers, the Processor shall ensure equivalent measures are in place in the recipient country or obtain individual consent as required under Article 28.
- The Processor shall cooperate with the Controller in responding to Data Subject requests for disclosure, correction, cessation of use, or deletion.
- The Processor shall notify the Controller without undue delay of any incident involving unauthorized access or leakage of Personal Data, to enable notification to the Personal Information Protection Commission (PPC) and affected individuals.
- The Processor shall retain Personal Data only for the period necessary for the agreed purposes and shall securely delete or return data upon completion of Processing.
- The Processor shall comply with the Security Principle under the Malaysia PDPA by implementing practical measures to protect Personal Data from loss, misuse, modification, unauthorized or accidental access, disclosure, alteration, or destruction.
- The Processor shall process Personal Data only for the purposes authorized by the Controller and shall not disclose data to any third party without the Controller's prior written consent.
- The Processor shall assist the Controller with obligations arising from 2025 and subsequent amendments, including mandatory breach notification to the Personal Data Protection Commissioner and affected Data Subjects.
- The Processor shall appoint a Data Protection Officer where required under the amended Malaysia PDPA.
- The Processor shall support the Controller in fulfilling Data Subject rights, including access and correction requests, within the prescribed timelines.
- The Processor shall retain Personal Data only for as long as necessary for the agreed purposes and shall securely dispose of data in accordance with the Retention Principle.
- The Processor shall process Personal Data only on the Controller's documented instructions and in compliance with the Mauritius Data Protection Act 2017.
- The Processor shall implement appropriate technical and organizational security measures to protect Personal Data, as required under the Mauritius DPA, including measures to prevent unauthorized access, disclosure, alteration, or destruction.
- The Processor shall assist the Controller in fulfilling Data Subject rights, including rights to access, rectification, erasure, and objection, within the prescribed timelines.
- The Processor shall not transfer Personal Data outside Mauritius unless the recipient country provides adequate protection or appropriate safeguards are in place (e.g., contractual clauses, consent, or authorization from the Data Protection Office).
- The Processor shall notify the Controller without undue delay of any Data Breach and shall cooperate with the Data Protection Office (DPO) as required.
- The Processor shall retain Personal Data only for as long as necessary for the agreed purposes and shall securely delete or return data upon termination of the engagement.
- The Processor (as Agent) shall process Personal Data only for the lawful purpose connected with the Controller's functions or activities (IPP 1), collect only what is necessary, and not use or disclose beyond authorized limits (IPPs 10–11).
- The Processor shall take reasonable steps under IPP 5 to protect Personal Data from loss, unauthorized access, use, modification, or disclosure.
- For any disclosure outside New Zealand, the Processor shall comply with IPP 12 by ensuring reasonable belief in comparable safeguards (e.g., via contractual terms, OPC model clauses, equivalent laws, or informed authorization from the individual).
- The Processor shall assist the Controller with access and correction requests (IPPs 6–7), complaints handling, and breach notifications under the Notifiable Data Breaches scheme (if serious harm is likely).
- The Processor shall comply with IPP 3A (notification for indirect collection, effective May 1, 2026) as applicable.
- The Processor shall retain Personal Data only for as long as necessary for the agreed purposes and shall securely dispose of or return data when no longer required.
- The Processor shall process Personal Data only on the Controller's documented instructions and for the agreed purposes, in compliance with the Oman PDPL.
- The Processor shall obtain explicit consent for cross-border transfers of Personal Data unless an exception applies and shall ensure recipient safeguards are in place.
- The Processor shall implement appropriate security measures to protect Personal Data from unauthorized access, loss, alteration, or disclosure.
- The Processor shall notify the Controller without undue delay of any Data Breach and shall assist with notifications from the relevant authority.
- The Processor shall support the Controller in fulfilling Data Subject rights, including access, correction, and erasure requests.
- The Processor shall retain Personal Data only for the period necessary to fulfill the agreed Processing purposes and shall securely delete or return data upon termination.
- The Processor shall process Personal Data only on the Controller's documented instructions and in compliance with Peru's PDPL (Law No. 29733) and its implementing regulations (Decree No. 003-2013-JUS).
- The Processor shall implement appropriate technical, organizational, and legal security measures to protect Personal Data, as required under the PDPL and its regulations.
- The Processor shall assist the Controller in fulfilling Data Subject rights, including rights to access, rectification, cancellation (deletion), and objection (ARCO rights), within the prescribed timelines.
- The Processor shall not transfer Personal Data outside Peru unless the recipient country provides adequate protection or an exception applies (e.g., contractual clauses, consent, or international treaty).
- The Processor shall notify the Controller without undue delay of any Data Breach and shall cooperate with the Controller in responding to inquiries from the Autoridad Nacional de Protección de Datos Personales (ANPDP).
- The Processor shall retain Personal Data only for as long as necessary for the agreed purposes and shall securely delete or return data upon termination of the engagement.
- The Processor (as Personal Information Processor or "PIP") shall process Personal Data only on documented instructions, implement reasonable security measures (organizational, physical, and technical), and notify the Controller of breaches without undue delay.
- Where applicable thresholds are met (e.g., more than 250 employees or sensitive data of more than 1,000 individuals), the Processor shall register data processing systems with the National Privacy Commission.
- The Processor shall appoint a Data Protection Officer and ensure any sub-PIPs comply with equivalent obligations.
- The Processor shall retain Personal Data only for as long as necessary to fulfill the specified Processing purposes and shall securely dispose of data thereafter.
- The Processor shall cooperate with the Controller and the National Privacy Commission in the event of any investigation, complaint, or compliance review.
- The Processor shall process Personal Data only for the purposes authorized by the Controller and in compliance with applicable Puerto Rico privacy laws, including the Puerto Rico Citizen Information on Data Banks Security Act (Act No. 111-2005) and any other applicable federal or territorial privacy requirements.
- The Processor shall implement reasonable security measures to protect Personal Data from unauthorized access, disclosure, or use.
- The Processor shall notify the Controller without undue delay of any Data Breach involving Personal Data of Puerto Rico residents, to enable the Controller to comply with applicable breach notification requirements.
- The Processor shall assist the Controller in responding to Data Subject requests as required under applicable Puerto Rico and U.S. federal privacy laws.
- The Processor shall retain Personal Data only for as long as necessary for the agreed Processing purposes and shall securely delete or return data upon termination.
- The Processor shall provide sufficient guarantees regarding the implementation of appropriate technical and organizational measures as required under Article 8 of the Saudi PDPL.
- The Processor shall process Personal Data only on the Controller's documented instructions and solely for the agreed purposes.
- The Processor shall notify SDAIA within 72 hours of becoming aware of a Data Breach where required and shall assist the Controller in notifying affected Data Subjects.
- The Processor shall use transfer mechanisms such as adequacy decisions, SCCs, or assessments approved by SDAIA for any cross-border transfer of Personal Data.
- The Processor shall support the Controller in fulfilling Data Subject rights, including rights of access, correction, and deletion under the Saudi PDPL.
- The Processor shall retain Personal Data only for as long as necessary for the specified purposes and shall securely delete or return data upon completion of Processing or termination of the engagement.
- The Processor (as Data Intermediary) shall process Personal Data only for the agreed purposes and in accordance with the Controller's documented instructions (PDPA Sections 24–26).
- The Processor shall notify the Controller of any Data Breach without undue delay to enable notification to the PDPC within the prescribed timelines where significant harm is likely.
- The Processor shall retain data only as necessary for the agreed purposes and shall securely delete or return Personal Data upon termination of the engagement.
- The Processor shall ensure transfers outside Singapore maintain comparable protection standards through contractual or other appropriate safeguards.
- The Processor shall assist with Do-Not-Call obligations if the Processing involves marketing communications.
- The Processor shall cooperate with the PDPC in any investigation or inquiry and shall maintain adequate records of Processing activities carried out on behalf of the Controller.
- The Processor (as Operator) shall process Personal Data only with the Controller's authorization and solely for the purposes specified in this DPA, in accordance with Section 21 of POPIA.
- The Processor shall implement appropriate security safeguards, including technical and organizational measures, to protect Personal Data against loss, damage, unauthorized destruction, or unlawful access.
- The Processor shall provide immediate breach notification to the Controller upon becoming aware of any compromise of Personal Data, to enable the Controller to notify the Information Regulator and affected Data Subjects as required under Section 22.
- The Processor shall treat all Personal Data as confidential and shall ensure that personnel authorized to process data are subject to appropriate confidentiality obligations.
- The Processor shall support the Controller in fulfilling Data Subject rights, including rights to access, correction, and deletion as provided under POPIA.
- The Processor shall securely delete or return all Personal Data upon termination of the engagement and shall not retain copies except as required by South African law.
- The Processor shall process Personal Data strictly in accordance with the Controller's instructions and the scope specified in this DPA, as required under PIPA.
- The Processor shall implement technical, administrative, and physical safeguards to protect Personal Data from unauthorized access, leakage, alteration, or destruction.
- For cross-border transfers, the Processor shall ensure adequate safeguards are in place through adequacy determinations, individual consent, or certification mechanisms as prescribed under PIPA.
- The Processor shall assist the Controller in responding to Data Subject rights requests, including access, correction, suspension of Processing, and deletion.
- The Processor shall notify the Controller without undue delay of any Data Breach and shall cooperate with the Personal Information Protection Commission (PIPC) as required.
- The Processor shall disclose the outsourcing arrangement and the identity of the Processor to Data Subjects as required under PIPA's entrustment notification provisions.
- The Processor shall process Personal Data per the Controller's orders as required under Section 40 of the Thailand PDPA and shall ensure binding contractual safeguards are in place.
- The Processor shall implement appropriate security measures to prevent unauthorized access, loss, alteration, or disclosure of Personal Data.
- The Processor shall assist the Controller with Data Subject rights requests, including access, correction, deletion, portability, and objection, within the timelines prescribed under the Thailand PDPA.
- The Processor shall notify the Controller without undue delay of any Data Breach, to enable the Controller to report to the PDPC Thailand and affected Data Subjects within the statutory timelines.
- For cross-border transfers, the Processor shall ensure adequate safeguards are in place, including adequacy determinations or contractual mechanisms as approved by the PDPC Thailand.
- The Processor shall maintain records of Processing activities and shall cooperate with the PDPC Thailand in any investigation or compliance inquiry.
- Processing shall be fair, transparent, and based on consent or another legal basis under UAE PDPL Article 4 and DIFC DPL Article 9.
- The Processor shall implement appropriate security measures to protect Personal Data from unauthorized access, loss, or disclosure.
- The Processor shall assist the Controller with DPIAs under DIFC DPL Article 32 and shall cooperate with the UAE Data Office and DIFC Commissioner as required.
- The Processor shall ensure adequacy or appropriate safeguards for cross-border transfers, including use of SCCs under DIFC DPL Article 27 or compliance with UAE PDPL Article 20.
- The Processor shall support the Controller in fulfilling Data Subject rights, including the rights of access, rectification, erasure, and objection to Processing.
- The Processor shall retain Personal Data only for as long as necessary for specified purposes and shall securely delete or return data upon termination of the engagement.
- The Processor shall act solely as a “Service Provider” or “Processor” under CCPA/CPRA and US State Privacy Laws and shall not sell, share, or use Personal Data for targeted advertising or cross-context behavioral advertising without consent.
- The Processor shall assist with consumer rights requests, including rights to access, deletion, correction, opt-out of sale or sharing, and the right to limit use of Sensitive Personal Data.
- The Processor shall conduct data protection assessments for high-risk Processing activities as required under applicable US State Privacy Laws.
- The Processor shall comply with de-identification requirements and shall not attempt to re-identify de-identified data.
- The Processor certifies that it understands and will comply with the restrictions on use, retention, and disclosure of Personal Data set forth in this DPA and applicable US State Privacy Laws.
- The Processor shall cooperate with the Controller in responding to verifiable consumer requests within the statutory timelines (e.g., 45 days under CCPA/CPRA).
Data Processing Clauses for Subcontractor Staffing Agencies (Sub-Processing of Personal Data)
This Annexure applies where the Controller, i.e., Infosys engages a subcontractor staffing agency ("Staffing Agency") that deploys its personnel ("Subcontractor Resources" or "Subcons") to perform services that involve the Processing of Personal Data. This Annexure governs the obligations of the Staffing Agency and its Subcontractor Resources in relation to the Processing of Personal Data under two scenarios: (a) where the Controller acts as a Controller processing Personal Data for its own internal purposes; and (b) where the Controller acts as a Processor on behalf of its client (the "Client"), and the Staffing Agency acts as a Sub-Processor. This Annexure forms an integral part of the DPA and supplements the obligations set out in the main body and Schedules. In the event of any conflict between this Annexure and the main body of the DPA, the provision that affords greater protection to Personal Data shall prevail. For the avoidance of doubt, this Annexure does not govern the Processing of the Subcontractor Resources' own employment or HR-related Personal Data; such processing is governed by the Staffing Agency's own privacy notices and agreements with its personnel.
- "Subcontractor Resources" or "Subcons" means individuals employed or engaged by the Staffing Agency who are deployed to perform services for or on behalf of the Controller.
- "Client" means any third-party entity on whose behalf the Controller acts as a Processor when processing Personal Data under a separate client engagement or services agreement.
- "Client Data" means Personal Data provided by or collected on behalf of the Client, which the Controller processes in its capacity as a Processor on behalf of the Client.
- "Internal Data" means Personal Data processed by the Controller for its own internal purposes (e.g., data of the Controller's own employees, customers, business contacts, or end users).
- "Sub-Staffing Agency" means any further staffing agency, recruitment agency, sub-agent, or sub-vendor engaged by the Staffing Agency to source or deploy Subcontractor Resources.
The following table sets out the role of each party under each processing scenario. The Parties shall indicate the applicable scenario(s) at the time of execution.
| Scenario | Data Type | Client / Data Owner | Controller's Role | Staffing Agency's Role | Subcontractor Resources' Role |
|---|---|---|---|---|---|
| Scenario A: Internal Processing | Internal Data | The Controller itself | Controller | Processor (via deployment of Subcontractor Resources) | Authorized personnel of the Staffing Agency, acting under the authority and instructions of the Controller |
| Scenario B: Client Processing | Client Data | The Client | Processor (on behalf of the Client) | Sub-Processor (via deployment of Subcontractor Resources) | Authorized personnel of the Staffing Agency, acting under the authority and instructions of the Controller as passed down from the Client |
- Under Scenario A, the Controller determines the purposes and means of Processing. The Staffing Agency acts as a Processor and shall ensure that its Subcontractor Resources process Internal Data solely on the Controller's documented instructions, in accordance with this DPA and Applicable Data Protection Laws.
- Under Scenario B, the Client is the ultimate Controller (or, in some cases, may itself be a Processor acting on behalf of another party). The Controller acts as a Processor on behalf of the Client under the terms of a separate client services agreement and data processing agreement between the Controller and the Client (the "Client DPA"). The Staffing Agency acts as a Sub-Processor, and its Subcontractor Resources process Client Data solely on the Controller's documented instructions, which reflect the instructions received by the Controller from the Client. The Staffing Agency acknowledges that it is bound not only by this DPA but also by the data protection obligations that flow down from the Client DPA to the extent communicated by the Controller.
- Under both scenarios, the Staffing Agency shall not independently determine the purposes or means of Processing and shall not use Personal Data for any purpose other than performing the services as instructed by the Controller.
- The Staffing Agency shall ensure that all Subcontractor Resources process Personal Data strictly in accordance with the Controller's documented instructions and only to the extent necessary to perform the services for which they are deployed.
- The Staffing Agency shall not and shall ensure that Subcontractor Resources do not process Personal Data for any purpose other than the agreed services, including but not limited to the Staffing Agency's own business purposes, marketing, analytics, profiling, or model training.
- If the Staffing Agency believes that an instruction from the Controller infringes Applicable Data Protection Laws, the Staffing Agency shall promptly inform the Controller before carrying out the instruction.
- The Staffing Agency shall ensure that all Subcontractor Resources who access or process Personal Data are bound by written confidentiality obligations that survive the termination of their engagement.
- Prior to granting any Subcontractor Resource access to Personal Data, the Staffing Agency shall ensure that such individual has received appropriate training in data protection, information security, acceptable use, and the specific obligations under this DPA.
- The Staffing Agency shall ensure that Subcontractor Resources complies with all applicable policies of the Controller (and, under Scenario B, the Client's policies as communicated by the Controller), including data protection policies, information security policies, acceptable use policies, and clean desk/clear screen policies.
- The Staffing Agency shall ensure that access to Personal Data by Subcontractor Resources is limited to what is strictly necessary for the performance of their assigned tasks (need-to-know principle).
- The Staffing Agency shall cooperate with the Controller in implementing role-based access controls and shall promptly inform the Controller of any changes to Subcontractor Resource assignments, role changes, or departures that affect access to Personal Data.
- The Staffing Agency shall not grant Subcontractor Resources access to systems, databases, or datasets beyond the scope authorized by the Controller.
- The Staffing Agency shall implement and maintain technical and organizational security measures at least equivalent to those set out in Schedule B of the DPA, to the extent applicable to its role in the processing chain.
- The Staffing Agency shall ensure that Subcontractor Resources comply with all security requirements specified by the Controller, including requirements relating to device management, remote access, use of portable storage media, printing and copying restrictions, screen lock policies, and data handling procedures.
- Where Subcontractor Resources Access Personal Data using the Staffing Agency's own infrastructure (e.g., laptops, networks, VPN), the Staffing Agency shall ensure that such infrastructure meets or exceeds the Controller's security standards and is subject to regular security assessments.
- The Staffing Agency shall promptly notify the Controller if it becomes aware of any security vulnerability, non-compliance, or risk relating to the Subcontractor Resources' handling of Personal Data.
- The Staffing Agency shall notify the Controller without undue delay, and at any event within forty-eight (48) hours, after becoming aware of any Data Breach involving Personal Data accessed or processed by Subcontractor Resources.
- The notification shall include, to the extent available: the nature of the breach; the identity of the Subcontractor Resource(s) involved; the categories and approximate volume of Personal Data affected; the likely consequences; and the measures taken or proposed to contain and remediate the breach.
- The Staffing Agency shall cooperate fully with the Controller in investigating and remediating the breach, preserving evidence, and fulfilling notification obligations to the Client (under Scenario B), supervisory authorities, and affected Data Subjects as required under Applicable Data Protection Laws.
- The Staffing Agency shall ensure that its agreements with Subcontractor Resources require immediate escalation of any suspected or actual Data Breach to the Staffing Agency.
- The Staffing Agency shall assist the Controller in fulfilling Data Subject rights requests relating to Personal Data processed by Subcontractor Resources, including requests for access, rectification, deletion, restriction, portability, objection, and withdrawal of consent, within the timelines required by Applicable Data Protection Laws.
- Where the Staffing Agency or a Subcontractor Resource receives a Data Subject rights request directly, the Staffing Agency shall promptly notify the Controller and shall not respond to the request without the Controller's instructions.
- The Staffing Agency shall maintain processes and systems that enable it to promptly locate, retrieve, rectify, or delete Personal Data processed by its Subcontractor Resources upon the Controller's instruction.
- The Staffing Agency shall assist the Controller in conducting data protection impact assessments, privacy impact assessments, and risk assessments where the services performed by Subcontractor Resources involve Processing that is likely to result in a high risk to Data Subjects.
- Under Scenario B, the Staffing Agency shall also assist the Controller in responding to impact assessment requests from the Client.
- The Staffing Agency shall ensure that Subcontractor Resources do not copy, download, extract, transmit, or retain any Personal Data except as strictly necessary to perform the assigned services and as authorized by the Controller.
- The Staffing Agency shall ensure that Subcontractor Resources do not store Personal Data on personal devices, unauthorized cloud services, removable media, or any location not approved by the Controller.
- The Staffing Agency shall ensure that no Personal Data is shared with or disclosed to the Staffing Agency's other clients, affiliates, or any third party, except as expressly authorized by the Controller in writing.
- Onboarding: Prior to granting a Subcontractor
Resource access to Personal Data, the Staffing Agency shall:
- Ensure the individual has completed all required background checks, identity verifications, and right-to-work verifications as required by the Controller's policies and Applicable Data Protection Laws.
- Ensure the individual has received and acknowledged the Controller's data protection, information security, acceptable use, and confidentiality policies.
- Ensure the individual has completed data protection awareness training appropriate to the nature of the Personal Data to be processed and the applicable jurisdiction(s).
- Provide the Controller with written confirmation that all pre-access requirements have been satisfied.
- Offboarding: Upon termination or completion of a
Subcontractor Resource's assignment, the Staffing Agency
shall:
- Promptly notify the Controller and cooperate in revoking all access credentials, system access, physical access, and equipment assigned to the departing individual.
- Ensure the departing individual returns all Controller property, Client property (under Scenario B), data, and confidential information.
- Ensure the departing individual has not retained any copies of Personal Data in any form.
- Confirm the completion of offboarding activities to the Controller in writing.
- The Staffing Agency shall not engage any Sub-Staffing Agency to deploy resources who will access or process Personal Data on behalf of the Controller without the Controller's prior written consent.
- Where a Sub-Staffing Agency is authorized, the Staffing Agency shall:
- Impose data protection obligations on the Sub-Staffing Agency that are at least equivalent to those set out in this Annexure, the main body of the DPA, and Schedule B.
- Remain fully liable to the Controller for the acts and omissions of any Sub-Staffing Agency and its deployed resources.
- Conduct due diligence on the Sub-Staffing Agency's data protection and information security practices prior to engagement and on a periodic basis thereafter.
- Maintain an up-to-date register of all authorized Sub-Staffing Agencies (see Section E below).
The following obligations apply in addition to Part II where Scenario A is selected (i.e., the Staffing Agency's Subcontractor Resources process Internal Data on behalf of the Controller acting as Controller for its own purposes).
- The Staffing Agency shall ensure that Subcontractor Resources process Internal Data only in accordance with the Controller's documented instructions, policies, and procedures, including any specific data handling guidelines issued for projects, business units, or data categories.
- The Staffing Agency shall not make any independent determination regarding the purposes or means of Processing Internal Data.
- The Staffing Agency shall ensure that Subcontractor Resources comply with all the Controller's internal data governance, data classification, data retention, acceptable use, and information security policies as communicated to the Staffing Agency.
- Where the Controller requires Subcontractor Resources to use specific systems, tools, or platforms for Processing Internal Data, the Staffing Agency shall ensure compliance with the Controller's instructions regarding the use and configuration of such systems.
- Upon completion of the services, termination of the engagement, or at the Controller's request, the Staffing Agency shall ensure that all Internal Data held by or accessible to its Subcontractor Resources is securely returned to the Controller or deleted in accordance with the Controller's instructions and Schedule B.
- The Staffing Agency shall provide written certification of deletion upon the Controller's request.
The following obligations apply in addition to Part II where Scenario B is selected (i.e., the Controller acts as a Processor on behalf of the Client, and the Staffing Agency's Subcontractor Resources process Client Data, making the Staffing Agency a Sub-Processor).
- The Staffing Agency acknowledges that the Controller is bound by the terms of a Client DPA between the Controller and the Client, and that the obligations under this Annexure reflect and give effect to the requirements imposed on the Controller by the Client DPA.
- The Controller shall communicate to the Staffing Agency, in writing, the relevant data protection requirements, processing instructions, and restrictions imposed by the Client DPA, to the extent necessary for the Staffing Agency to fulfil its obligations. The Staffing Agency shall comply with all such requirements as if they were directly binding on the Staffing Agency.
- Where the Client DPA imposes obligations that are more restrictive than those set out in this DPA (e.g., shorter breach notification timelines, enhanced security requirements, restrictions on data locations, or prohibitions on specific types of Processing), the Staffing Agency shall comply with the more restrictive requirements communicated by the Controller.
- The Staffing Agency shall ensure that Subcontractor Resources process Client Data solely on the Controller's documented instructions, which in turn reflect the instructions received from the Client. The Staffing Agency shall not process Client Data for any purpose other than the specific services authorized under the Controller's engagement with the Client.
- The Staffing Agency acknowledges that it has no direct relationship with the Client and shall not contact the Client directly regarding data processing matters unless expressly authorized by the Controller.
- The Staffing Agency acknowledges that the Client may have audit and inspection rights under the Client DPA, which may extend to the Staffing Agency as a Sub-Processor. The Staffing Agency shall cooperate with any audit or inspection requested by the Controller on behalf of the Client, or directly by the Client with the Controller's authorization, at reasonable intervals and upon reasonable notice.
- The Staffing Agency shall make available to the Controller (and, where required, to the Client) all information necessary to demonstrate compliance with this Annexure and Applicable Data Protection Laws.
- The Staffing Agency shall ensure that Client Data is logically or physically segregated from the Staffing Agency's own data, the Controller's Internal Data, and data belonging to any other client of the Staffing Agency or the Controller, unless the Controller expressly instructs otherwise.
- Subcontractor Resources assigned to process Client Data shall not access Internal Data or data belonging to other clients of the Controller, unless separately authorized by the Controller.
- Where the Client imposes specific security standards, certifications, or compliance requirements (e.g., industry-specific standards such as PCI DSS, HIPAA, SOX, or sector-specific data protection requirements), the Controller shall communicate these requirements to the Staffing Agency, and the Staffing Agency shall ensure that its Subcontractor Resources comply with such requirements.
- The Staffing Agency shall cooperate with the Controller in providing evidence of compliance with Client-specific requirements, including certifications, attestations, questionnaire responses, and audit reports.
- In addition to the breach notification obligations set out in Part II (Section B.5), the Staffing Agency acknowledges that the Controller is required to notify the Client of Data Breaches involving Client Data within the timelines specified in the Client DPA (which may be shorter than the 48-hour period set out in Section B.5).
- The Staffing Agency shall therefore notify the Controller as soon as possible and in any event within twenty-four (24) hours of becoming aware of any suspected or confirmed Data Breach involving Client Data, to enable the Controller to meet its obligations to the Client.
- The Staffing Agency shall provide all information and cooperation necessary for the Controller to prepare and submit breach notifications to the Client, and onward to supervisory authorities and affected Data Subjects, in accordance with the Client DPA and Applicable Data Protection Laws.
- Where the Staffing Agency or a Subcontractor Resource receives a Data Subject rights request relating to Client Data, the Staffing Agency shall immediately notify the Controller and shall not respond to the request directly. The Controller shall manage the response in coordination with the Client as required under the Client DPA.
- The Staffing Agency shall assist the Controller in locating, retrieving, rectifying, or deleting Client Data processed by its Subcontractor Resources within the timelines communicated by the Controller (which may reflect the Client's requirements).
- Upon completion of the services related to Client Data, termination of the Controller's engagement with the Client, termination of the Staffing Agency's engagement, or at the Controller's request, the Staffing Agency shall ensure that all Client Data held by or accessible to its Subcontractor Resources is securely returned to the Controller or deleted in accordance with the Controller's instructions, the Client DPA requirements, and Schedule B.
- The Staffing Agency shall provide written certification of deletion to the Controller upon request, and the Controller may share such certification with the Client.
- The Staffing Agency acknowledges that the Controller's engagement with the Client may terminate independently of the Master Agreement between the Controller and the Staffing Agency. Upon notification by the Controller that a Client engagement has terminated, the Staffing Agency shall immediately cease all Processing of the affected Client Data, comply with the offboarding and data return/deletion obligations set out in this Annexure, and confirm completion to the Controller in writing.
E.1 Transfer Obligations
- Where Subcontractor Resources are in a jurisdiction different from the jurisdiction of the Controller, the Client (under Scenario B), or the Data Subjects whose Personal Data is being processed, the Staffing Agency shall comply with the cross-border transfer obligations set out in Section 3.8 of the DPA and Schedule D.
- The Staffing Agency shall inform the Controller of all jurisdictions from which Subcontractor Resources access or process Personal Data and shall obtain the Controller's prior written consent before any Subcontractor Resource accesses Personal Data from a new jurisdiction.
- Under Scenario B, the Staffing Agency acknowledges that cross-border transfers of Client Data may also be subject to the Client DPA and the Client's approval. The Controller shall communicate any Client-imposed transfer restrictions to the Staffing Agency, and the Staffing Agency shall comply with such restrictions.
- The Staffing Agency shall make available to the Controller all information necessary to demonstrate compliance with this Annexure and shall allow for audits, including inspections, by the Controller or an auditor mandated by the Controller (or, under Scenario B, by the Client with the Controller's authorization), at reasonable intervals and upon reasonable notice.
- The Staffing Agency shall maintain records of all Subcontractor Resources who access or process Personal Data, including records of training completed, access granted and revoked, assignments, and offboarding confirmations.
- The Staffing Agency shall promptly remediate any findings or non-conformities identified through audits or inspections and shall report remediation actions to the Controller.
- The Staffing Agency shall indemnify and hold the Controller harmless against any and all losses, claims, damages, fines, penalties, costs, and expenses (including reasonable legal fees) arising from or in connection with any breach by the Staffing Agency, its Subcontractor Resources, or any Sub-Staffing Agency of this Annexure, the DPA, or Applicable Data Protection Laws in relation to the Processing of Personal Data.
- Under Scenario B, the Staffing Agency's indemnification obligation extends to losses arising from claims by the Client or the Client's supervisory authority attributable to acts or omissions of the Staffing Agency, its Subcontractor Resources, or any Sub-Staffing Agency.
- Upon termination or expiry of the Master Agreement, the staffing engagement, or this DPA (whichever occurs first), the Staffing Agency shall comply with the offboarding obligations set out in Section B.9 and the data return and deletion obligations set out in Sections C.3 and D.8, as applicable.
- The obligations of the Staffing Agency under this Annexure with respect to confidentiality, data retention, deletion, indemnification, cooperation with audits and regulatory inquiries, and compliance with surviving Client DPA obligations shall survive termination of the engagement.
The following table shall be maintained by the Staffing Agency and provided to the Controller upon request, listing all authorized Sub-Staffing Agencies whose deployed resources access or process Personal Data on behalf of the Controller:
| Sub-Staffing Agency Name | Jurisdiction / Location | Scope of Services | Applicable Scenario (A / B / Both) | Categories of Personal Data Accessed | Date of Engagement | Controller Consent Date |
|---|---|---|---|---|---|---|
| [Name] | [Country] | [Description] | [A / B / Both] | [Categories] | [Date] | [Date] |
| [Name] | [Country] | [Description] | [A / B / Both] | [Categories] | [Date] | [Date] |